Firebase Server Change Crashed iOS Apps, No Update Needed
A bad Firebase Analytics config payload crashed iOS apps on launch Sept. 28-29. Google says the fix is server-side, but the SDK still can't survive it.

A malformed response from a Google server crashed iOS apps that use Firebase Analytics, starting at 00:41 UTC on Sept. 29, 2026, and no app update caused it or can prevent a repeat. Google says it fixed the payload, but the SDK’s failure to handle bad input is the part developers still own (firebase-ios-sdk issue #16728).
What happened
The crash is an NSInvalidArgumentException: -[__NSDictionaryM setObject:forKeyedSubscript:]: key cannot be nil. According to the issue, it fires right after the Analytics SDK receives an HTTP 200 from its sdk-exp experiments endpoint and tries to process the response. Reporters said multiple already-shipped builds, including apps on Firebase SDK 12.14.0, began crashing at the same moment, which points away from client code. Crashes tended to hit on first launch, with later launches surviving, consistent with the SDK throttling its fetches.
A pinned reply from the Firebase team said Google “fully rolled out a fix” at 19:52 US/PDT on Sept. 28, which is 02:52 UTC on Sept. 29, about two hours after the crashes began. The team said no SDK update is required, but that some app instances may keep crashing for up to four hours after the rollout because of caching. Follow-up crash reports were filed as issues #16730 and #16731.
The reaction
Hacker News commenters split. Some pointed out that a server-side change should not be able to take down a client, and one noted there is still no sign of an SDK release that tolerates malformed input. Others said teams that bundle third-party SDKs accept this risk. Developer Gergely Orosz wrote on X that the SDK “started to crash ALL iOS apps that were using it.” That is his characterization; the Firebase team has not published a count of affected apps.
Our take
“No SDK update required” is accurate about the fix and dodges the cause. The server sent bad data once. The SDK turned it into a fatal crash on every affected device because it doesn’t validate the response. Until Firebase ships that hardening, any config-shaped payload from Google can do this again, and app developers have no way to catch it in testing.
What to do
- Check Crashlytics for
key cannot be nilspikes between 00:41 and about 07:00 UTC on Sept. 29. A crash alert in that window was probably this. - Don’t ship a hotfix for it. Nothing in your code changed.
- If you don’t use Analytics experiments, consider whether that app needs the Analytics SDK at all, since the crash path runs through it.
- Ask Firebase support to confirm a client-side fix is planned, and watch issue #16728 for it.


